IP Library › Granted Patent US 12,659,324
Granted Patent B1
US 12,659,324 · App. 17/342,240 · Granted Jun 16, 2026

Systems and methods for creating and presenting relationships within information technology data

Inventors: Andrew Warner (Peachtree Corners, GA); Sudha Kalyanasundaram (Cumming, GA); Faith A. Brumfield (Johns Creek, GA); Ashish Desai (Suwanee, GA); Steven Stiles (Scottsdale, AZ); Amanda Yang (Snellville, GA); Yolanda Brumfield (Johns Creek, GA); Alexander R. Schneck (Roswell, GA); Cesar B. Acosta (Atlanta, GA); Christopher Chickoree (Atlanta, GA)
Assignee: State Farm Mutual Automobile Insurance Company
H04L63/1425G06N3/08H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,659,324
App. No.
17/342,240
Granted
Jun 16, 2026
Kind
B1
Abstract

In one aspect, a computing system including a processor in communication with at least one memory may be provided. The processor may be configured to: (i) connect to a plurality of data sources in a nodal network including a plurality of nodes; (ii) determine, for each node of the plurality of nodes, a relationship to at least one other node of the plurality of nodes; (iii) generate, based upon the determined relationships between nodes, a mapping including each node of the plurality of nodes and each relationship of the determined relationships; (iv) analyze each relationship of the determined relationships to determine at least one threat; (v) determine at least one solution for the at least one threat; and/or (vi) cause display of the at least one threat and the at least one solution.

Claims (79)

1 . A data security protocol computing system configured to identify potential data security threats and deploy solutions to the potential data security threats, the data security protocol computing system comprising a processor in communication with at least one memory, the processor configured to:

connect to a plurality of data sources in a nodal network comprising a plurality of nodes, wherein each data source of the plurality of data sources is associated with a node type of a plurality of node types and comprises at least one node of the plurality of nodes;

determine, for each node of the plurality of nodes, a relationship to at least one other node of the plurality of nodes;

generate, based upon the determined relationships between nodes, a mapping including each node of the plurality of nodes and each relationship of the determined relationships as an edge of a plurality of edges;

cause a machine learning model to analyze each relationship of the determined relationships, wherein the machine learning model is trained in a plurality of stages, wherein each stage of the plurality of stages is associated with one or more training sets comprising at least one of previously-deployed solutions to threats, threats, or non-threats;

receive an output from the machine learning model comprising at least one data security threat associated with at least one node of the plurality of nodes, at least one edge of the plurality of edges between the at least one node and a different node of the plurality of nodes, and at least one data security solution, the at least one data security solution associated with the at least one data security threat and comprising at least one of a software patch or a new version of software;

cause display of the at least one edge in a first display format at a client computing device, the first display format associated with the at least one data security threat;

automatically implement the at least one data security solution based on the output from the machine learning model; and

update display of the at least one edge at the client computing device from the first display format to a second display format, the second display format associated with the at least one data security solution being implemented.

2 . The data security protocol computing system of claim 1 , wherein the processor is further configured to:

cause display of each node of the plurality of nodes and each edge of the plurality of edges;

receive an input selecting at least one of i) the at least one node of the plurality of nodes and ii) the at least one edge of the plurality of edges; and

cause display of at least one non-compliance and at least one solution associated with the input.

3 . The data security protocol computing system of claim 1 , wherein the processor is configured to:

cause display of each node of the plurality of nodes and each edge of the plurality of edges; and

modify display of each edge of the plurality of edges associated with the at least one data security threat in order to communicate the at least one edge of the plurality of edges that is associated with the at least one data security threat.

4 . The data security protocol computing system of claim 1 , wherein the processor is further configured to:

determine one or more nodes of the plurality of nodes accessible by a user of the data security protocol computing system based upon a security level associated with the user; and

cause display of only the one or more nodes accessible by the user and any threats associated therewith.

5 . The data security protocol computing system of claim 1 , wherein the machine learning model comprises a neural network, and wherein the processor is further configured to:

create a first training set of the one or more training sets comprising a plurality of threats including the at least one data security threat;

train the neural network in a first stage of the plurality of stages using the first training set;

create a second training set of the one or more training sets comprising the first training set and non-threats that are incorrectly identified as threats after the first stage of training; and

train the neural network in a second stage of the plurality of stages using the second training set.

6 . The data security protocol computing system of claim 1 , wherein the plurality of node types includes at least one of: assets, representing at least one computing device, policies, representing company policies, controls, representing data security controls, and data security protocols, representing defined data security protocols.

7 . The data security protocol computing system of claim 1 , wherein the processor is further configured to cause display of the mapping including each node and each edge at the client computing device.

8 . The data security protocol computing system of claim 7 , wherein the processor is further configured to:

receive an input at the client computing device, the input selecting a node; and

filter display of the mapping as including edges associated with the node and not other edges.

9 . The data security protocol computing system of claim 8 , wherein the processor is further configured to cause display of node data associated with the node based upon the input, the node data comprising at least one of an asset name associated with the node or an asset type associated with the node.

10 . A computer-implemented method implemented by a computing system including a processor in communication with at least one memory, the method comprising:

connecting to a plurality of data sources in a nodal network comprising a plurality of nodes, wherein each data source of the plurality of data sources is associated with a node type of a plurality of node types and comprises at least one node of the plurality of nodes;

determining, for each node of the plurality of nodes, a relationship to at least one other node of the plurality of nodes;

generating, based upon the determined relationships between nodes, a mapping including each node of the plurality of nodes and each relationship of the determined relationships as an edge of a plurality of edges;

causing a machine learning model to analyze each relationship of the determined relationships, wherein the machine learning model is trained in a plurality of stages, wherein each stage of the plurality of stages is associated with one or more training sets comprising at least one of previously-deployed solutions to threats, threats, and non-threats;

receiving an output from the machine learning model comprising at least one data security threat associated with at least one node of the plurality of nodes, at least one edge of the plurality of edges between the at least one node and a different node of the plurality of nodes, and at least one data security solution, the at least one data security solution associated with the at least one data security threat and comprising at least one of a software patch or a new version of software;

causing display of the at least one edge in a first display format at a client computing device, the first display format associated with the at least one data security threat;

automatically implementing the at least one data security solution based on the output from the machine learning model; and

updating display of the at least one edge at the client computing device from the first display format to a second display format, the second display format associated with the at least one data security solution being implemented.

11 . The computer-implemented method of claim 8 further comprising:

causing display of each node of the plurality of nodes and each edge of the plurality of edges;

receiving an input selecting at least one of i) at least one node of the plurality of nodes and ii) the at least one edge of the plurality of edges; and

causing display of at least one non-compliance and at least one solution associated with the input.

12 . The computer-implemented method of claim 10 , further comprising:

causing display of each node of the plurality of nodes and each edge of the plurality of edges; and

modifying display of each edge of the plurality of edges associated with the at least one data security threat in order to communicate the at least one edge of the plurality of edges that is associated with the at least one data security threat.

13 . The computer-implemented method of claim 10 further comprising:

determining one or more nodes of the plurality of nodes accessible by a user of the computing system based upon a security level associated with the user; and

causing display of only the one or more nodes accessible by the user and any threats associated therewith.

14 . The computer-implemented method of claim 10 , wherein the machine learning model comprises a neural network, and wherein the method further comprises:

creating a first training set of the one or more training sets comprising a plurality of threats including the at least one data security threat;

training the neural network in a first stage of the plurality of stages using the first training set;

creating a second training set of the one or more training sets comprising the first training set and non-threats that are incorrectly identified as threats after the first stage of training; and

training the neural network in a second stage of the plurality of stages using the second training set.

15 . The computer-implemented method of claim 10 , wherein the plurality of node types includes at least one of: assets, representing at least one computing device, policies, representing company policies, controls, representing data security controls, and data security protocols, representing defined data security protocols.

16 . At least one non-transitory computer-readable storage media having computer-executable instructions embodied thereon, wherein when executed by a computing system including at least one processor in communication with at least one memory device, the computer-executable instructions cause the at least one processor to:

connect to a plurality of data sources in a nodal network comprising a plurality of nodes, wherein each data source of the plurality of data sources is associated with a node type of a plurality of node types and comprises at least one node of the plurality of nodes;

determine, for each node of the plurality of nodes, a relationship to at least one other node of the plurality of nodes;

generate, based upon the determined relationships between nodes, a mapping including each node of the plurality of nodes and each relationship of the determined relationships as an edge of a plurality of edges;

cause a machine learning model to analyze each relationship of the determined relationships, wherein the machine learning model is trained in a plurality of stages, wherein each stage of the plurality of stages is associated with one or more training sets comprising at least one of previously-deployed solutions to threats, threats, and non-threats;

receive an output from the machine learning model comprising at least one data security threat associated with at least one node of the plurality of nodes, at least one edge of the plurality of edges between the at least one node and a different node of the plurality of nodes, and at least one data security solution, the at least one data security solution associated with the at least one data security threat and comprising at least one of a software patch or a new version of software;

cause display of the at least one edge in a first display format at a client computing device, the first display format associated with the at least one data security threat;

automatically implement the at least one data security solution based on the output from the machine learning model; and

update display of the at least one edge at the client computing device from the first display format to a second display format, the second display format associated with the at least one data security solution being implemented.

17 . The at least one non-transitory computer-readable storage media of claim 16 , wherein the computer-executable instructions further cause the processor to:

cause display of each node of the plurality of nodes and each edge of the plurality of edges;

receive an input selecting at least one of i) at least one node of the plurality of nodes and ii) the at least one edge of the plurality of edges; and

cause display of at least one non-compliance and at least one solution associated with the input.

18 . The at least one non-transitory computer-readable storage media of claim 16 , wherein the computer-executable instructions further cause the processor to:

cause display of each node of the plurality of nodes and each edge of the plurality of edges; and

modify display of each edge of the plurality of edges associated with the at least one data security threat in order to communicate the at least one edge of the plurality of edges that is associated with the at least one data security threat.

19 . The at least one non-transitory computer-readable storage media of claim 16 , wherein the computer-executable instructions further cause the processor to:

determine one or more nodes of the plurality of nodes accessible by a user of the computing system based upon a security level associated with the user; and

cause display of only the one or more nodes accessible by the user and any threats associated therewith.

20 . The at least one non-transitory computer-readable storage media of claim 16 , wherein the machine learning model comprises a neural network, and wherein the computer-executable instructions further cause the processor to:

create a first training set of the one or more training sets comprising a plurality of threats including the at least one data security threat;

train the neural network in a first stage of the plurality of stages using the first training set;

create a second training set of the one or more training sets comprising the first training set and non-threats that are incorrectly identified as threats after the first stage of training; and

train the neural network in a second stage of the plurality of stages using the second training set.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2021
From: WARNER, ANDREW; KALYANASUNDARAM, SUDHA; BRUMFIELD, FAITH A.; DESAI, ASHISH; STILES, STEVEN; YANG, AMANDA; BRUMFIELD, YOLANDA; SCHNECK, ALEXANDER R.; ACOSTA, CESAR B.; CHICKOREE, CHRISTOPHER
To: STATE FARM MUTUAL AUTOMOBILE INSURANCE COMPANY
Reel/Frame 056473/0234 →
References Cited (136)
US 5592600A · De Pauw et al. · 1997 [cited by applicant]
US 6535227B1 · Fox et al. · 2003 [cited by applicant]
US 6836893B2 · Pinard · 2004 [cited by applicant]
US 7757271B2 · Amdur et al. · 2010 [cited by applicant]
US 8285822B2 · K. · 2012 [cited by applicant]
US 8583678B2 · Vainer et al. · 2013 [cited by applicant]
US 8640086B2 · Bonev et al. · 2014 [cited by applicant]
US 8674993B1 · Fleming et al. · 2014 [cited by applicant]
US 8738414B1 · Nagar et al. · 2014 [cited by applicant]
US 8769412B2 · Gill et al. · 2014 [cited by applicant]
US 8930395B2 · Sharma et al. · 2015 [cited by applicant]
US 8938435B2 · Swaminathan et al. · 2015 [cited by applicant]
US 9087361B2 · Mirra et al. · 2015 [cited by applicant]
US 9276774B2 · Manser · 2016 [cited by applicant]
US 9311082B2 · Bonev et al. · 2016 [cited by applicant]
US 9383900B2 · Flores et al. · 2016 [cited by applicant]
US 9411557B1 · Cartey et al. · 2016 [cited by applicant]
US 9544192B2 · Ruggeri · 2017 [cited by applicant]
US 9652559B2 · Byrne et al. · 2017 [cited by applicant]
US 9876801B1 · Scott et al. · 2018 [cited by applicant]
US 9935851B2 · Gandham et al. · 2018 [cited by applicant]
US 9967158B2 · Pang et al. · 2018 [cited by applicant]
US 10013717B2 · Posch et al. · 2018 [cited by applicant]
US 10116530B2 · Yadav et al. · 2018 [cited by applicant]
US 10116531B2 · Alizadeh Attar et al. · 2018 [cited by applicant]
US 10129237B2 · Cashman et al. · 2018 [cited by applicant]
US 10176445B2 · Venna et al. · 2019 [cited by applicant]
US 10222965B1 · Dennis et al. · 2019 [cited by applicant]
US 10248391B2 · Heiss · 2019 [cited by applicant]
US 10305758B1 · Bhide · 2019 [cited by examiner]
US 10320630B2 · Gandham et al. · 2019 [cited by applicant]
US 10482542B1 · Jain · 2019 [cited by applicant]
US 10496468B2 · Gefen et al. · 2019 [cited by applicant]
US 10505827B2 · Parandehgheibi et al. · 2019 [cited by applicant]
US 10516585B2 · Parandehgheibi et al. · 2019 [cited by applicant]
US 10528897B2 · Labat et al. · 2020 [cited by applicant]
US 10528958B2 · Yang et al. · 2020 [cited by applicant]
US 10534518B2 · Ranganathan et al. · 2020 [cited by applicant]
US 10594542B2 · Jeyakumar et al. · 2020 [cited by applicant]
US 10623282B2 · Deen et al. · 2020 [cited by applicant]
US 10628015B2 · Johnson et al. · 2020 [cited by applicant]
US 10657482B2 · Kurjanowicz et al. · 2020 [cited by applicant]
US 10666494B2 · Zafer et al. · 2020 [cited by applicant]
US 10693903B2 · Linde et al. · 2020 [cited by applicant]
US 10721266B1 · Herman-Saffar · 2020 [cited by examiner]
US 10728120B2 · Beyer · 2020 [cited by applicant]
US 10748226B2 · Van De Sande et al. · 2020 [cited by applicant]
US 10761687B2 · Fletcher et al. · 2020 [cited by applicant]
US 10769159B2 · Lyons et al. · 2020 [cited by applicant]
US 10795909B1 · Bond et al. · 2020 [cited by applicant]
US 10797973B2 · Parandehgheibi et al. · 2020 [cited by applicant]
US 10802698B1 · Draper et al. · 2020 [cited by applicant]
US 10818053B2 · Pushpoth et al. · 2020 [cited by applicant]
US 11074511B2 · Patil · 2021 [cited by examiner]
US 11159555B2 · Hadar · 2021 [cited by examiner]
US 11533324B2 · Walsh · 2022 [cited by examiner]
US 11550560B2 · Yang · 2023 [cited by examiner]
US 11727142B2 · James Stephen · 2023 [cited by examiner]
US 11805140B2 · Baidya · 2023 [cited by examiner]
US 11829471B2 · Jin · 2023 [cited by examiner]
US 11847214B2 · Dichiu · 2023 [cited by examiner]
US 11922162B2 · A · 2024 [cited by examiner]
US 11949698B1 · Vincent · 2024 [cited by examiner]
US 11960610B2 · Hercock · 2024 [cited by examiner]
US 12045343B2 · Coull · 2024 [cited by examiner]
US 12088608B2 · Konda · 2024 [cited by examiner]
US 12120134B2 · Rogers · 2024 [cited by examiner]
US 20020113816A1 · Mitchell et al. · 2002 [cited by applicant]
US 20030028859A1 · Street et al. · 2003 [cited by applicant]
US 20060080656A1 · Cain · 2006 [cited by examiner]
US 20070150562A1 · Stull et al. · 2007 [cited by applicant]
US 20070214179A1 · Hoang · 2007 [cited by applicant]
US 20080072321A1 · Wahl · 2008 [cited by examiner]
US 20080163063A1 · Bonev et al. · 2008 [cited by applicant]
US 20080301765A1 · Nicol · 2008 [cited by examiner]
US 20090031239A1 · Coleran et al. · 2009 [cited by applicant]
US 20100192212A1 · Raleigh · 2010 [cited by examiner]
US 20100293112A1 · Prahlad et al. · 2010 [cited by applicant]
US 20110126111A1 · Gill · 2011 [cited by examiner]
US 20120090028A1 · Lapsley · 2012 [cited by examiner]
US 20140189870A1 · Singla · 2014 [cited by examiner]
US 20140280909A1 · Gosink · 2014 [cited by examiner]
US 20150066933A1 · Kolodziej et al. · 2015 [cited by applicant]
US 20150074612A1 · Antipa · 2015 [cited by applicant]
US 20150113024A1 · Howe · 2015 [cited by applicant]
US 20150120521A1 · Howe · 2015 [cited by applicant]
US 20150332054A1 · Eck · 2015 [cited by examiner]
US 20160134588A1 · Falkowitz · 2016 [cited by examiner]
US 20160232370A1 · Rissanen et al. · 2016 [cited by applicant]
US 20160269249A1 · Maes · 2016 [cited by examiner]
US 20160323693A1 · Rathod · 2016 [cited by applicant]
US 20160328668A1 · B'Far et al. · 2016 [cited by applicant]
US 20160357424A1 · Pang et al. · 2016 [cited by applicant]
US 20160359915A1 · Gupta · 2016 [cited by examiner]
US 20170048266A1 · Hovor · 2017 [cited by examiner]
US 20170085446A1 · Zhong · 2017 [cited by examiner]
US 20170222873A1 · Lee et al. · 2017 [cited by applicant]
US 20170279696A1 · Vasseur · 2017 [cited by examiner]
US 20180004948A1 · Martin · 2018 [cited by examiner]
US 20180013650A1 · Khanal · 2018 [cited by examiner]
US 20180144243A1 · Hsieh · 2018 [cited by examiner]
US 20180159887A1 · DiGiambattista · 2018 [cited by examiner]
US 20180189416A1 · Lee et al. · 2018 [cited by applicant]
US 20180197183A1 · Mcbennett · 2018 [cited by applicant]
US 20180276254A1 · Whitlock et al. · 2018 [cited by applicant]
US 20180295154A1 · Crabtree · 2018 [cited by examiner]
US 20190018904A1 · Russell et al. · 2019 [cited by applicant]
US 20190034254A1 · Nataraj · 2019 [cited by examiner]
US 20190036963A1 · Ahad · 2019 [cited by examiner]
US 20190098032A1 · Murphey · 2019 [cited by examiner]
US 20190121979A1 · Chari · 2019 [cited by examiner]
US 20190342324A1 · Nawy · 2019 [cited by examiner]
US 20200011784A1 · Chalumuri et al. · 2020 [cited by applicant]
US 20200066012A1 · Pushpoth et al. · 2020 [cited by applicant]
US 20200137104A1 · Hassanzadeh · 2020 [cited by examiner]
US 20200169565A1 · Badawy · 2020 [cited by examiner]
US 20200211103A1 · Searson et al. · 2020 [cited by applicant]
US 20200241711A1 · Pandian et al. · 2020 [cited by applicant]
US 20200259700A1 · Bhalla · 2020 [cited by examiner]
US 20200287807A1 · Zhong et al. · 2020 [cited by applicant]
US 20200293305A1 · Yang · 2020 [cited by examiner]
US 20200293912A1 · Williams et al. · 2020 [cited by applicant]
US 20200293970A1 · Hwang · 2020 [cited by examiner]
US 20200303059A1 · Trindade Rodrigues et al. · 2020 [cited by applicant]
US 20200334237A1 · Yousaf et al. · 2020 [cited by applicant]
US 20200412767A1 · Crabtree · 2020 [cited by examiner]
US 20210152574A1 · Maida · 2021 [cited by examiner]
US 20240195815A1 · Yang · 2024 [cited by examiner]
US 20240372889A1 · Beck · 2024 [cited by examiner]
US 20250045391A1 · Agranonik · 2025 [cited by examiner]
US 20250227117A1 · Shahbaz · 2025 [cited by examiner]
WO 2013185166A1 · 2013 [cited by applicant]
WO 2017069548A1 · 2017 [cited by applicant]
WO 2020206204A1 · 2020 [cited by applicant]
Zhang et al.; A Machine Learning-based Approach for Automated Vulnerability Remediation Analysis; 2020; retrieved from the Internet https://ieeexplore.ieee.org/abstract/document/9162309; pp. 1-9. (Year: 2020). [cited by examiner]
Zhang et al.; A machine Learning-based Approach for Automated Vulnerability Remediation Analysis; 2020; retrieved from the internet https://ieeexplore.ieee.org/abstract/document/9162309; pp. 1-9, as printed. (Year: 2020… [cited by examiner]